Public Domain means you can legally take their code, riddle it with malware, and distribute, claiming that's the real and true Direct File source code, and you are its author. What you do with malware is a different legal issue of course.
So I'm not sure proving you are commit owner by signing it is really helpful if anyone can do it as well, and there's no copyright holder to decide who's right.
Let's say you see a green checkmark on GitHub that confirms the commit was really made by GitHub user @totally_legit_government_absolutely_not_hacker.
Unless you already have their public GPG key in your private keychain, and you marked it as "trusted" previously, there's not really much more info to that.
UPDATE: besides, the government is like a million people, some of them are malicious actors.